/* ---- Google Analytics Code Below */
Showing posts with label RiskIQ. Show all posts
Showing posts with label RiskIQ. Show all posts

Friday, April 08, 2022

RiskIQ Looks at sites Targeting Ukraine

 Examining targeted Threat Intelligence

RiskIQ Threat Intelligence Roundup: Trickbot, Magecart, and More Fake Sites Targeting Ukraine 

APRIL 07, 2022,     BY TEAM RISKIQ

Threat intelligence is more crucial than ever to attack surface management and cyber resilience in today's volatile threat landscape. RiskIQ continues to leverage our global telemetry to develop relevant, actionable intelligence that gives security teams line-of-sight to attackers and threat systems and infrastructure.

This week's roundup again builds on powerful research published by the cybersecurity community about cyberattacks against Ukrainian citizens, refugees, and armed forces, including fraudulent sites attempting to fool people that want to donate money. It also breaks down new research in collaboration with the Microsoft Defender for IoT Section 52 research team about Trickbot malware targeting Mikrotik routers, updates with Magecart, and additional insight into nation-state activity targeting Chinese casinos.

What's New in C2

Trickbot Abuse of Compromised MikroTik Routers for Command and Control: In collaboration with Section 52, RiskIQ researchers investigated MikroTik routers acting as reverse proxies for Trickbot command and control (C2). Section 52's article details how threat actors compromise MikroTik devices and configure them to work as C2 reverse-proxies for Trickbot malware. We analyzed examples of compromised MikroTik routers in RiskIQ data and document indicators that can help identify devices under threat actor control.

Based on new findings, indicators surfaced by Section 52, and previous third-party research, RiskIQ created detection logic that enables our systems to flag compromised MikroTik routers working as communication channels for Trickbot C2. Be sure to read more about our findings and access the more than 70 new indicators in our Threat Intelligence Portal (TIP).

Recent Magecart-Injected URLs and C2 Domains: Today, digital credit skimming malware like Magecart affects hundreds of e-commerce sites and shouldn't be overlooked. February saw a wave of attacks, which showed "low-hanging fruit" is still available for these actors, which take advantage of new vulnerabilities and issues with plugins and other third-party code. Between March 15th and 21st, RiskIQ detected 149 Magecart and skimmer-injected URLs and 186 unique C2 domains used by known Magecart operatives.

A Closer Look at Campaigns Targeting Ukraine   (See remainder of article at link) 

Tuesday, July 20, 2021

RiskIQ Joins Microsoft: Good

 Risk is ultimately 'the thing'.   Both in terms of analyzing how what you do is risky in various contexts.   And also in terms of external threats that increase your risk.   Both the risk of what you plan to do, and the risk of what others plan to do to you.   These days the two work together.  Which is the way we described it in some of our analytics efforts.  Microsoft needs both of these.  I hope they learn this from RiskIQ.   Will watch how this evolves.  

Joining Microsoft is the Next Stage of the RiskIQ Journey

JULY 12, 2021, BY LOU MANOUSOS

Today Microsoft announced its intent to acquire RiskIQ, representing the next stage of our journey that's been more than a decade in the making. We couldn't be more excited to join forces to enable the global community to defend against the rising tide of cyberattacks. 

RiskIQ was conceived to preserve the original promise of the Internet—bringing people together. Connecting people across the world and making sure those connections are safe is something worth defending every single day. That hasn’t changed.

When RiskIQ first launched, the digital enterprise was shifting to the Internet, the start of digital transformation. SaaS; Mobile apps were suddenly everywhere; the cloud was becoming the basis of development—essentially, the Internet was becoming the network, and the extended enterprise was born. ...' 

Monday, July 12, 2021

Microsoft Better Tighten Up

Good, they have gotten to some real issues far too late.  Being the premier general computational systems provider, they need to fix threats better and faster,  if they don't want to lose that distinction.   I still like microsoft's capabilities, but can see the slipping.  Ransomware and other related threats are a huge challenge.  Now. 

Microsoft acquires cybersecurity firm RiskIQ as the threat of ransomware intensifies

Microsoft is trying to tighten up its security

By Tom Warren@tomwarren  Jul 12, 2021, 11:48am EDT

Microsoft is officially acquiring RiskIQ, a security software vendor. RiskIQ provides management tools and threat intelligence gathering against a wide range of cyberattacks across Microsoft’s own cloud services, AWS, on-premises servers, and supply chain attacks. While Microsoft hasn’t valued the deal, Bloomberg reported that the company is said to be paying more than $500 million for RiskIQ.

The cloud-based RiskIQ software detects security issues across networks and devices, and the company lists Box, the US Postal Service, BMW, Facebook, and American Express as customers. RiskIQ was originally founded in 2009 and has gradually become an important player in analyzing security threats.

Microsoft hasn’t laid out a detailed plan for how it will integrate RiskIQ into its own security offerings, but it’s bound to utilize RiskIQ’s software across Microsoft 365 Defender, Microsoft Azure Defender, and Microsoft Azure Sentinel eventually.  .. ' 

Sunday, November 01, 2020

RiskIQ and Ransomware

 Useful detail.

RiskIQ Has Released Its Corpus of Infrastructure and IOCs Related to Ryuk Ransomware  By TEAM RISKIQ

Ryuk Ransomware has flooded US hospitals, threatening to shut down their operations when they're needed most. Ryuk now accounts for a third of all ransomware attacks in 2020, with its operators finding success while many healthcare organizations are most vulnerable. However, the cybersecurity community is coming together to combat this rash of attacks, combining resources to provide network defenders with alerts and intelligence to protect our healthcare institutions. 

To do our part, RiskIQ released the entirety of the infrastructure related to the Ryuk strain of ransomware collected by RiskIQ's Internet Intelligence Graph. These expansive, unique holdings complement recent public efforts by US federal agencies and researchers at FireEye, exposing all known infrastructure these criminals use to execute their attacks. FireEye also publicly released all relevant Ryuk indicators of compromise (IOCs) it has observed in 2020. ... '